spf-discuss
[Top] [All Lists]

Re: ESMTPA vs. ESMTPS

2005-08-16 14:31:06
william(at)elan.net wrote:

SMTP with TLS with self-signed certificate will do fine and
much better then CRAM-MD5

Point.  OTOH this is not more KISS (in other words I never
tried hard to understand it, let alone implement it in REXX)

<http://purl.net/xyzzy/src/md5.cmd> (REXX MD5 stuff)
How about sha256.cmd?

AFAIK SHA-1 is not really better than MD5, it's only longer.

And SHA-256 is again longer.  I watch the "hash WG" hoping
for better ideas.  At the moment I often see discussions in
the rough direction of "let's take SHA-256 and truncate it".

Why is that better than say "let's use MD5 for odd bytes,
again MD5 for the even bytes, and concatenate the hashes" ?

                       Bye, Frank



<Prev in Thread] Current Thread [Next in Thread>